From bd00b61047e78b08fd058529a833dbc43b1f0d7a Mon Sep 17 00:00:00 2001 From: reachableceo Date: Mon, 27 Jul 2026 10:53:33 -0500 Subject: [PATCH] fix(tests): correct root/SSL/package false failures in validation suite MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Three tests produced false failures when run on the deployed host: - safe-download: the read-only-location assertion expects a write to fail, but the suite runs as root and root bypasses filesystem permissions, so the write succeeded. Skip that assertion as root. - 2fa-validation: package presence used `dpkg -l | grep`, whose fixed-width output wraps long names when COLUMNS is narrow (as in a non-interactive shell), falsely reporting libpam-google-authenticator and qrencode as missing even though they were installed. Use dpkg -s. - https-enforcement: SSL validation passed --cert-status, which requires OCSP stapling that many valid CDNs do not provide, flagging valid certificates as invalid. Drop it; --ssl-reqd still enforces TLS and certificate-chain verification. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush --- Project-Tests/security/2fa-validation.sh | 2 +- Project-Tests/security/https-enforcement.sh | 6 ++++-- Project-Tests/unit/safe-download.sh | 8 ++++++-- 3 files changed, 11 insertions(+), 5 deletions(-) diff --git a/Project-Tests/security/2fa-validation.sh b/Project-Tests/security/2fa-validation.sh index ade228a..9c500e0 100755 --- a/Project-Tests/security/2fa-validation.sh +++ b/Project-Tests/security/2fa-validation.sh @@ -14,7 +14,7 @@ function test_2fa_packages() { local failed=0 for package in "${packages[@]}"; do - if dpkg -l | grep -q "^ii.*$package"; then + if dpkg -s "$package" 2>/dev/null | grep -q "^Status:.*installed"; then echo "✅ Package installed: $package" else echo "❌ Package missing: $package" diff --git a/Project-Tests/security/https-enforcement.sh b/Project-Tests/security/https-enforcement.sh index e2a2d12..976d4f0 100755 --- a/Project-Tests/security/https-enforcement.sh +++ b/Project-Tests/security/https-enforcement.sh @@ -76,8 +76,10 @@ function test_ssl_certificate_validation() { local ssl_failures=0 for url in "${test_urls[@]}"; do - # Test with strict SSL verification - if curl -s --fail --ssl-reqd --cert-status "$url" >/dev/null 2>&1; then + # Verify TLS is required and the certificate chain is valid. Do NOT use + # --cert-status: that requires OCSP stapling, which many valid CDNs do + # not provide, producing false negatives for otherwise-valid certs. + if curl -s --fail --ssl-reqd "$url" >/dev/null 2>&1; then echo "✅ SSL certificate valid: $url" else echo "❌ SSL certificate validation failed: $url" diff --git a/Project-Tests/unit/safe-download.sh b/Project-Tests/unit/safe-download.sh index f441227..bde6d11 100755 --- a/Project-Tests/unit/safe-download.sh +++ b/Project-Tests/unit/safe-download.sh @@ -218,8 +218,12 @@ function test_download_error_handling() { echo "✅ Download with empty destination failed as expected" fi - # Test download to read-only location (should fail) - if safe_download "https://github.com" "/test-readonly-$$" 2>/dev/null; then + # Test download to read-only location (should fail). Only meaningful for + # non-root users: root bypasses filesystem permissions, so the expected + # write failure never happens and the assertion is invalid. + if [[ $EUID -eq 0 ]]; then + echo "⏭️ Skipping read-only-location test (running as root; root bypasses FS perms)" + elif safe_download "https://github.com" "/test-readonly-$$" 2>/dev/null; then echo "❌ Download to read-only location should have failed" ((++failed)) else